VYPR
Unrated severityNVD Advisory· Published Aug 31, 2001· Updated Apr 16, 2026

CVE-2000-1190

CVE-2000-1190

Description

Local users can exploit a symlink vulnerability in imwheel-solo to modify arbitrary files via the .imwheelrc file.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Local users can exploit a symlink vulnerability in imwheel-solo to modify arbitrary files via the .imwheelrc file.

Vulnerability

The imwheel-solo utility in the imwheel package follows symbolic links when processing the user's ~/.imwheelrc configuration file. This allows a local attacker to create a symlink from ~/.imwheelrc to any file on the system, causing imwheel-solo to write to that file with the privileges of the setuid process. The vulnerability affects all versions of imwheel prior to a fix, as noted in the Bugtraq discussion [2].

Exploitation

An attacker with local shell access can create a symbolic link from ~/.imwheelrc to a target file (e.g., /etc/shadow). Upon executing imwheel-solo, the program will follow the symlink and write to the target file, effectively allowing arbitrary file modification. No authentication beyond local user access is required [2].

Impact

Successful exploitation enables an attacker to overwrite arbitrary files on the system, including sensitive files such as /etc/shadow or /etc/passwd. This can lead to privilege escalation, denial of service, or complete compromise of the system's integrity and confidentiality.

Mitigation

No official patch is explicitly mentioned in the provided references. However, users should remove the setuid bit from imwheel-solo or restrict its execution to trusted users. Upgrading to a patched version of the imwheel package (if available from the distribution vendor) is recommended. The vulnerability is old and likely addressed in later releases.

AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.